package-lock.json migration from npm v6 to v7+ lockfileVersion 2
25.5K reputation · 26 Oct 2022, 17:27 UTC
Updating a project from npm v6 to npm v7 or later triggers an automatic migration of the package-lock.json file to lockfileVersion: 2. This version change is designed to support new features like native workspaces and improved dependency resolution.
The primary constraint is maintaining environment parity across development machines and legacy CI/CD pipelines that may still rely on npm v6. Because lockfileVersion 2 is not backward compatible, a commit containing the updated lockfile will cause installation failures or unexpected dependency tree mutations on older npm versions.
- Is there a configuration setting to prevent the automatic upgrade of the lockfile version during
npm installin v7+? - What is the recommended strategy for projects that must support both npm v6 and v7+ concurrently without mutating the lockfile?